Fixed-Fee Engagement

Find out what the assessor will find, two weeks before they do.

A fixed-scope technical audit of your cloud environment, delivery pipeline, or data platform against the framework you are being held to. You get a written control mapping, a prioritized list of findings with the architectural fix for each, and an effort estimate per item. The report is yours whether or not you ever hire us again.

Fixed fee · no hourly billing
$15,000
2 weeks · single platform, up to 20 services
Written report · roadmap · effort estimates
Book a scoping call

Why teams start here.

Nobody hands a stranger a six-figure infrastructure project on the strength of a discovery call. The audit exists so you do not have to. It is small enough to approve without a committee, short enough to finish before your next milestone, and it produces something concrete regardless of what you do next.

It also solves the harder problem, which is that most teams cannot scope their own remediation. They know something is wrong, they do not know how much, and every vendor proposal they receive is priced against a guess. Two weeks of engineering replaces that guess with a document your team, your CFO, and your assessor can all read.

Roughly half of audit clients do the remediation themselves. That is a fine outcome. We would rather you have an accurate roadmap you execute in-house than an inaccurate one that turns into an engagement neither of us enjoys.

What you receive.

D/01

Control mapping

Every relevant control mapped to what your system actually does, with the specific CFR section, 800-53 family, or trust services criterion it answers to.

D/02

Prioritized findings

What fails, ranked by the order an assessor will hit it, with the architectural fix for each. Written for engineers, not for a binder.

D/03

Effort estimates

Engineer-days per finding so you can budget the remediation, sequence it against your roadmap, or price it out to a vendor.

D/04

Evidence gap list

What your system currently cannot prove. Usually the most uncomfortable section, and the one that saves the most time later.

How the two weeks run.

Week 1 — Evidence

We look at the system, not the documentation.

  • Read-only access to cloud accounts, pipeline, and IaC
  • Architecture and data flow walkthrough with your engineers
  • Evidence pull: logs, retention, identity, access history
  • Two working sessions, roughly 90 minutes each
Week 2 — Findings

We write it up and walk you through it.

  • Control mapping and findings drafted
  • Effort estimates attached to each item
  • Live readout with your team, questions answered
  • Final written report delivered

Frameworks we audit against.

You name the framework and the target. We map to it.

HIPAA Security Rule FedRAMP Moderate FedRAMP High SOC 2 Type II HITRUST CSF CMMC 2.0 NIST SP 800-53 NIST SP 800-171

What happens after.

Three things typically follow, and we are genuinely indifferent between the first two. You execute the roadmap in-house with the estimates as your plan. You take it to another vendor and get accurate bids against a real scope instead of a guess. Or you engage us for the build, in which case the audit findings become the statement of work and we start from a scope both sides already agree on.

Build engagements run 8 to 12 weeks at $50,000 to $100,000 fixed fee, and teams with ongoing obligations often move onto a continuous compliance retainer after handoff. See the full practice list for what that covers.

Questions.

What do I actually receive?
A written report with a control mapping of your environment against the framework you name, a prioritized findings list, the architectural fix for each, and an effort estimate per finding. It is written for engineers to act on, not for a compliance binder.
Do I have to hire you for the remediation?
No. The report is yours and it is written so your own team can execute it. Roughly half of audit clients do exactly that. We would rather you have an accurate roadmap than an ongoing dependency.
What does it cover, and what does it not?
It covers the technical layer: cloud architecture, CI/CD pipeline, data platform, identity, logging, and evidence. It does not cover workforce training, policy authoring, vendor management, or the administrative safeguards a GRC consultant handles. We audit the systems, not the paperwork.
Is this a certification or a formal assessment?
No. We are an engineering firm, not an accredited assessment organization, and we are not a 3PAO. This is a technical readiness audit that tells you what an assessor will find before they find it. The separation is deliberate: assessors cannot remediate their own findings without an independence conflict, which is why teams engage us alongside their assessor rather than instead of one.
What if my environment is bigger than 20 services?
The $15,000 fee covers a single platform up to roughly 20 services, which fits most teams. Larger or multi-platform estimates are scoped on the call and quoted before anything starts. You will never receive an invoice you did not agree to in advance.
How quickly can you start?
Usually two to three weeks from signature, sooner if you have a fixed assessment date. Tell us the deadline on the first call and we will say plainly whether we can meet it.

Book a scoping call.

Thirty minutes. Bring your architecture and your deadline. We will confirm the audit is the right starting point, scope it against your actual environment, and send a written proposal within 48 hours. If you do not need an audit, we will tell you on the call.

Book a 30-minute scoping call
Want a number first? Run the estimator to see your control count and first-cycle cost — no email required.